
Researchers at Check Point discovered a vulnerability in ChatGPT that allowed an attacker to surreptitiously access data from services connected to an AI user’s account, including Gmail.
The issue stemmed from the isolated environments where ChatGPT executes code and performs specific tasks.
While these environments—associated with different user accounts—were intended to be completely segregated, they could all access a shared internal JFrog Artifactory service used for downloading software components. The service’s configuration allowed one environment to write data while another could read it. Effectively, the service became a hidden communication channel between accounts, the researchers noted.
The researchers demonstrated how an attacker could use this channel to transmit a command such as “get a list of my emails.”
Check Point reported the vulnerability to OpenAI, and the company subsequently disabled the affected service.